Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-31 Thread Zac Medico
On 10/31/2016 01:34 AM, Michał Górny wrote: > The major difference between a developer key and an automated key is > that the latter is far easier target. I think we can trust Gentoo > developers to at least have their keys encrypted. I suppose most of > them don't 'git log -p' the commits their si

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-31 Thread Kristian Fiskerstrand
On 10/31/2016 09:34 AM, Michał Górny wrote: > The major difference between a developer key and an automated key is > that the latter is far easier target. I think we can trust Gentoo > developers to at least have their keys encrypted. I suppose most of > them don't 'git log -p' the commits their si

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-31 Thread Michał Górny
On Sun, 30 Oct 2016 15:41:55 -0700 Zac Medico wrote: > On 10/30/2016 03:32 PM, Michał Górny wrote: > > On Sun, 30 Oct 2016 14:58:59 -0700 > > Zac Medico wrote: > > > >> On 10/30/2016 01:44 PM, Michał Górny wrote: > >>> Hi, everyone. > >>> > >>> Just a quick note: I've prepared a simple tool [1]

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-31 Thread Michał Górny
On Sun, 30 Oct 2016 15:36:16 -0700 Zac Medico wrote: > I'm merging in Michał's reply from the related "[gentoo-portage-dev] > [PATCH] [sync] Increase the default git sync-depth to 10" thread. > > On 10/30/2016 02:58 PM, Zac Medico wrote: > > On 10/30/2016 01:44 PM, Michał Górny wrote: > >> Hi, e

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-30 Thread Zac Medico
On 10/30/2016 03:32 PM, Michał Górny wrote: > On Sun, 30 Oct 2016 14:58:59 -0700 > Zac Medico wrote: > >> On 10/30/2016 01:44 PM, Michał Górny wrote: >>> Hi, everyone. >>> >>> Just a quick note: I've prepared a simple tool [1] to verify clones of >>> gentoo-mirror repositories. It's still early W

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-30 Thread Zac Medico
I'm merging in Michał's reply from the related "[gentoo-portage-dev] [PATCH] [sync] Increase the default git sync-depth to 10" thread. On 10/30/2016 02:58 PM, Zac Medico wrote: > On 10/30/2016 01:44 PM, Michał Górny wrote: >> Hi, everyone. >> >> Just a quick note: I've prepared a simple tool [1] t

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-30 Thread Michał Górny
On Sun, 30 Oct 2016 14:58:59 -0700 Zac Medico wrote: > On 10/30/2016 01:44 PM, Michał Górny wrote: > > Hi, everyone. > > > > Just a quick note: I've prepared a simple tool [1] to verify clones of > > gentoo-mirror repositories. It's still early WiP but can be easily used > > to verify a clone: >

Re: [gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-30 Thread Zac Medico
On 10/30/2016 01:44 PM, Michał Górny wrote: > Hi, everyone. > > Just a quick note: I've prepared a simple tool [1] to verify clones of > gentoo-mirror repositories. It's still early WiP but can be easily used > to verify a clone: > > $ ./verify-repo gentoo > [/var/db/repos/gentoo] > Untrust

[gentoo-dev] OpenPGP verification for gentoo-mirror repos

2016-10-30 Thread Michał Górny
Hi, everyone. Just a quick note: I've prepared a simple tool [1] to verify clones of gentoo-mirror repositories. It's still early WiP but can be easily used to verify a clone: $ ./verify-repo gentoo [/var/db/repos/gentoo] Untrusted signature on 42ccdf48d718287e981c00f25caea2242262906a (yo